Re: [Dtls-iot] Updated BOF information

Göran Selander <goran.selander@ericsson.com> Tue, 30 July 2013 15:04 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: dtls-iot@ietfa.amsl.com
Delivered-To: dtls-iot@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 097F111E81FD for <dtls-iot@ietfa.amsl.com>; Tue, 30 Jul 2013 08:04:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.123
X-Spam-Level:
X-Spam-Status: No, score=-4.123 tagged_above=-999 required=5 tests=[AWL=-1.825, BAYES_00=-2.599, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u9zCIuVB7qE2 for <dtls-iot@ietfa.amsl.com>; Tue, 30 Jul 2013 08:04:19 -0700 (PDT)
Received: from sesbmg20.ericsson.net (sesbmg20.ericsson.net [193.180.251.56]) by ietfa.amsl.com (Postfix) with ESMTP id 668DB11E8213 for <dtls-iot@ietf.org>; Tue, 30 Jul 2013 08:04:16 -0700 (PDT)
X-AuditID: c1b4fb38-b7f456d000002e83-71-51f7d5ed3a2e
Received: from ESESSHC018.ericsson.se (Unknown_Domain [153.88.253.125]) by sesbmg20.ericsson.net (Symantec Mail Security) with SMTP id 95.69.11907.DE5D7F15; Tue, 30 Jul 2013 17:04:14 +0200 (CEST)
Received: from ESESSMB303.ericsson.se ([169.254.3.247]) by ESESSHC018.ericsson.se ([153.88.183.72]) with mapi id 14.02.0328.009; Tue, 30 Jul 2013 17:04:13 +0200
From: Göran Selander <goran.selander@ericsson.com>
To: "Kumar, Sandeep" <sandeep.kumar@philips.com>, Zach Shelby <zach@sensinode.com>, "dtls-iot@ietf.org" <dtls-iot@ietf.org>
Thread-Topic: [Dtls-iot] Updated BOF information
Thread-Index: AQHOjP2v/AOJ6b+WEEqY8fPKKtThWZl82SKAgAAtFACAAB8OgP//6H0AgABEW4A=
Date: Tue, 30 Jul 2013 15:04:13 +0000
Message-ID: <F3AD00FA8C16C24298F85A1A14F03E432A6E1FFC@ESESSMB303.ericsson.se>
In-Reply-To: <BE6D13F6A4554947952B39008B0DC015344912F1@011-DB3MPN1-026.MGDPHG.emi.philips.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.3.2.130206
x-originating-ip: [153.88.183.146]
Content-Type: multipart/mixed; boundary="_004_F3AD00FA8C16C24298F85A1A14F03E432A6E1FFCESESSMB303erics_"
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrJIsWRmVeSWpSXmKPExsUyM+Jvre67q98DDdYt47dY3L6L1WLJ4UWM FrumrGVzYPZYsuQnk8eBA7uZPFZs72MKYI7isklJzcksSy3St0vgylizoIOx4MQepop3u/6y NzDemsPUxcjBISFgIrHljHUXIyeQKSZx4d56ti5GLg4hgaOMEi++PGaGcJYwSvS0X2UEqWIT cJU48OAdE4gtIlArsfnjZlYQW1hAX+LO++mMEHEDiQM79jKCLBAR8JM4ND8IJMwioCpx4OJa ZhCbV8BX4uDOK2CtnAJxEsubt7CD2IxAR3w/tQZsPLOAuMStJ/OZII4TkXh48TQbhC0q8fLx P7BeUQE9iZtnWlgh4koSPzZcYoHozZT4tXQuG8QuQYmTM5+wTGAUmYVk7CwkZbOQlEHE8yU2 LpgJZetJ3Jg6hQ3C1pZYtvA1M4StKzHj3yGoGmuJi88XsWCq0ZH4/a0LqldR4vbVqayzgEHK LLCSUeJ28xdGmKL7k06xwBRN6X7IvoCRbxUjR3FqcVJuupHBJkZg9B/c8ttiB+PlvzaHGKU5 WJTEebfonQkUEkhPLEnNTk0tSC2KLyrNSS0+xMjEwSnVwNi2vnifxfn/elqClpobv2xccFF5 9SlBXpu4T11TFJYfn+ifLj/93K1vhm2OXApz9u/hXKW8fLfE54pAV4EL7Toztr7e/ayeY2a2 HM/e3TtUXgvP0Np/a36d+C4290ad86dPimw908GUnXizfYddVduDnJzbu9yLD9/t2PaNUb7x 82uVA4pKZp1KLMUZiYZazEXFiQAXIPX7zAIAAA==
Subject: Re: [Dtls-iot] Updated BOF information
X-BeenThere: dtls-iot@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DTLS for IoT discussion list <dtls-iot.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dtls-iot>
List-Post: <mailto:dtls-iot@ietf.org>
List-Help: <mailto:dtls-iot-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Jul 2013 15:04:28 -0000

Hi Sandeep and all,

I fully agree that there is a bigger picture to be considered and that DTLS must be supported. I am also interested in the areas you list but to keep the discussion focused I may be important to find a initial common denominator where a number of people could contribute  and then build upon that.

Olaf is arranging a lunch meeting tomorrow for the authorization discussions,  anyone interested in that can join. We'll meet  after the morning session (~11:35) in the Wintergarten which is in front of the LA Cafe.


Regards,
Göran


From: <Kumar>, Sandeep <sandeep.kumar@philips.com<mailto:sandeep.kumar@philips.com>>
Date: Tuesday, July 30, 2013 2:59 PM
To: Göran Selander <goran.selander@ericsson.com<mailto:goran.selander@ericsson.com>>, Zach Shelby <zach@sensinode.com<mailto:zach@sensinode.com>>, "dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>" <dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>>
Subject: RE: [Dtls-iot] Updated BOF information

Hi Göran and all

I share the view that authorization is important for constrained devices, and key provisioning during this process provides advantages. However the final solution should also look at the larger problem of bootstrapping, general key management and revocation which are all inter-related in some way. Reusing DTLS for this would be preferred to reduce the need for yet another security protocol on these devices. We had a draft in LWIG (draft-keoh-lwig-dtls-iot-01) which discusses the use of DTLS for the key management, we assumed authorizations were being done with acls. And as Sye mentioned during CoRe, we had some similar work done with assertions and would be interested to join any discussions you guys plan to have.

Regards
Sandeep


From: dtls-iot-bounces@ietf.org<mailto:dtls-iot-bounces@ietf.org> [mailto:dtls-iot-bounces@ietf.org] On Behalf Of Göran Selander
Sent: Tuesday, July 30, 2013 2:24 PM
To: Zach Shelby; dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>
Subject: Re: [Dtls-iot] Updated BOF information

Hi Zach,

Sorry for being out of sync. You answered 1-2 before I sent my mail. And we maintain the coordination with CORE by keeping the discussion on that list.

On point 3, that is also about "optimising the use of DTLS in IoT" so is addressing the high level scope of DICE. I can't say yet if there is any impact on the DTLS profile or group keys with the DTLS record layer but we can take this discussion in the DICE BOF.


Thanks,
Göran


From: Göran Selander <goran.selander@ericsson.com<mailto:goran.selander@ericsson.com>>
Date: Tuesday, July 30, 2013 12:32 PM
To: Corinna Schmitt <schmitt@ifi.uzh.ch<mailto:schmitt@ifi.uzh.ch>>, Olaf Bergmann <bergmann@tzi.org<mailto:bergmann@tzi.org>>
Cc: Zach Shelby <zach@sensinode.com<mailto:zach@sensinode.com>>, "dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>" <dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>>
Subject: Re: [Dtls-iot] Updated BOF information

Hi Corinna, Olaf,

I'm also interested in this discussion.

I didn't intend to complain on lack of feedback. Here are my concerns:

  1.  To find a home for work on authorization and access control in constrained environments. The proposals on the table are really building on DTLS and COAP, so either CORE or DICE seems right to me. In the CORE WG there were a set of people showing hands of interest.
  2.  To be able to work on this now as there is a potential dependence on other ongoing things (e.g. access control in resource directory).
  3.  To make sure that the CORE and "DTLS in constrained environments"-related questions brought up in these drafts are coordinated with CORE and DICE. This includes stuff like DTLS client and server key provisioning schemes alternative to the CoAP security modes and the use of these for DoS mitigation in DTLS.
Regards,
Göran



From: Corinna Schmitt <schmitt@ifi.uzh.ch<mailto:schmitt@ifi.uzh.ch>>
Date: Tuesday, July 30, 2013 11:51 AM
To: Olaf Bergmann <bergmann@tzi.org<mailto:bergmann@tzi.org>>
Cc: Zach Shelby <zach@sensinode.com<mailto:zach@sensinode.com>>, "dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>" <dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>>
Subject: Re: [Dtls-iot] Updated BOF information

Dear Olaf,

thanks for your remark.
I think authentication is a big topic especially for constraint devices.

And yes, I agree for team up.
Due to many travelling I will arrive in Berlin late afternoon and have to leave tomorrow evening again.
Perhaps we can find some time to discuss it  as soon as possible. Tomorrow morning I am free. So if any one has time we can meet.
I stay at the Pestana Berlin Tiergarten, but will be at the meeting location after breakfast.

For the dinner tonight I have no ticket. So I cannot join if no one has one for me.

Regards,
Corinna




Am 30.07.13 10:20, schrieb Olaf Bergmann:

Zach Shelby <zach@sensinode.com><mailto:zach@sensinode.com> writes:



Hi Corinna,



On Jul 30, 2013, at 7:16 AM, Corinna Schmitt <schmitt@ifi.uzh.ch><mailto:schmitt@ifi.uzh.ch> wrote:



Just for information concerning our draft

http://tools.ietf.org/html/draft-schmitt-two-way-authentication-for-iot-00:

We already started to implemented a solution and evaluated a little

bit. So we would be glad if our draft will be approved and stay in

DICE.

Your draft was actually discussed yesterday in the CoRE WG meeting in

the scope of general authentication and authorisation in CoRE. This

subject will be out of scope for the first DICE charter as we already

have a couple concrete problems to solve. It is not clear where the

"AA" work will end up, probably in some other new working group, or

maybe in some future re-chartering of DICE.

The discussion yesterday was a bit low on the guidance level how to

proceed. Even if this topic is not the most pressing for DICE, I highly

recommend to work on this space *now*.



Corinna, maybe we could team up with the other authors of the relevant

drafts to find out what the next steps are? We had a quick talk with

Göran yesterday, and he also had the impression that the WG could have

been more active in giving feedback on these drafts.



Gruesse

Olaf

_______________________________________________

dtls-iot mailing list

dtls-iot@ietf.org<mailto:dtls-iot@ietf.org>https://www.ietf.org/mailman/listinfo/dtls-iot

--
[cid:image001.png@01CE8D32.A3327FC0]

________________________________
The information contained in this message may be confidential and legally protected under applicable law. The message is intended solely for the addressee(s). If you are not the intended recipient, you are hereby notified that any use, forwarding, dissemination, or reproduction of this message is strictly prohibited and may be unlawful. If you are not the intended recipient, please contact the sender by return e-mail and destroy all copies of the original message.